首页 | 本学科首页   官方微博 | 高级检索  
     检索      

The Anomaly Detection in SMTP Traffic Based on Leaky Integrate-and-Fire Model
作者姓名:罗浩  方滨兴  云晓春
作者单位:School of Computer Science and Technology Harbin Inst. of Technology Harbin 150001 China,School of Computer Science and Technology Harbin Inst. of Technology Harbin 150001 China,School of Computer Science and Technology Harbin Inst. of Technology Harbin 150001 China
基金项目:NationalNaturalScienceFoundationofChina(No.60403033)
摘    要:Introduction TheSMTP1]isusedasthebasisformost electronicmail.EmailisthemostpopularInternet servicenow2],anditallowspeopletocommuni-catebyexchangingelectronicmessagesglobally.Thesemessagescanbedeliveredinafewseconds toacoupleofhours.Anaddedattractionisthe relativelylowcostofsendinglargemessages.Combined,thesebenefitsgiveusersaconvincing argumentforaccesstoemail,andthustheconnec-tionoftheirsystemstotheInternet.SMTPisasimpleprotocolandcontainsonlya fewbasiccommands.Thereareseveralsecurity …

关 键 词:通信量  探测方法  积分  模型
文章编号:1007-1172(2006)02-0165-07
收稿时间:2005-10-10

The Anomaly Detection in SMTP Traffic Based on Leaky Integrate-and-Fire Model
LUO Hao,FANG Bin-xing,YUN Xiao-chun.The Anomaly Detection in SMTP Traffic Based on Leaky Integrate-and-Fire Model[J].Journal of Shanghai Jiaotong university,2006,11(2):165-171.
Authors:LUO Hao  FANG Bin-xing  YUN Xiao-chun
Abstract:This paper investigated an effective and robust mechanism for detecting simple mail transfer protocol (SMTP) traffic anomaly. The detection method cumulates the deviation of current delivering status from history behavior based on a weighted sum method called the leaky integrate-and-fire model to detect anomaly. The simplicity of the detection method is that the method need not store history profile and low computation overhead, which makes the detection method itself immunes to attacks. The performance is investigated in terms of detection probability, the false alarm ratio, and the detection delay. The results show that leaky integrate-and-fire method is quite effective at detecting constant intensity attacks and increasing intensity attacks. Compared with the non-parametric cumulative sum method, the evaluation results show that the proposed detection method has shorter detection latency and higher detection probability.
Keywords:anomaly detection  leaky integrate-and-fire model  SMTP traffic
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号